A finance colleague receives an email that looks like it came from a regular supplier. The logo is right, the tone is familiar, and the invoice lands at the busiest point of the month. One changed bank detail can turn a routine payment into an expensive incident.
Knowing how to assess phishing risk means looking beyond whether staff can spot a suspicious email. Phishing succeeds when a convincing message meets a gap in process, technology or decision-making. A useful assessment identifies those gaps, ranks the business impact and gives your team a clear plan to reduce exposure without slowing down day-to-day work.
Start with the business impact, not the inbox
Phishing is not only an email security problem. It can lead to fraud, account takeover, ransomware, data loss, service disruption and regulatory exposure. The risk is different for every business because the assets, workflows and consequences are different.
Begin by identifying what an attacker could gain if they compromised a user account or persuaded an employee to take action. For most organisations, the priority assets include payment processes, payroll information, customer and employee data, Microsoft 365 or Google Workspace accounts, remote access tools, cloud administration portals and senior leadership communications.
Then ask a practical question: what would happen if access to each asset was lost, misused or exposed for one working day? A compromised shared mailbox may create inconvenience. A compromised finance account with authority to amend supplier details can create an immediate financial loss. A compromised administrator account may affect the entire organisation.
This creates a risk picture based on operational reality rather than generic threat scores. It also helps leadership understand why phishing deserves investment alongside infrastructure resilience and business continuity planning.
How to assess phishing risk across people, process and technology
A complete phishing assessment should examine three connected areas. Weakness in any one of them can make the others less effective.
Assess who is most likely to be targeted
Phishing campaigns are rarely random. Criminals research public information, supplier relationships, job roles and organisational changes to make messages more believable. Review the people and teams who handle money, sensitive data, privileged access or high volumes of external communication.
Finance, payroll, HR, IT support, executives, procurement and customer-facing teams commonly face a higher level of targeting. That does not mean other staff are low risk. It means these groups may need more focused controls and more realistic training.
Look at working patterns too. New starters, temporary staff, hybrid workers and teams under intense deadline pressure may be more vulnerable because they are still learning processes or have less opportunity to verify unusual requests. A phishing risk assessment should avoid blaming individuals. The purpose is to identify where the business has made a costly mistake easy to make.
Review the processes attackers try to exploit
Many successful phishing incidents exploit an approval weakness rather than a technical failure. A criminal may impersonate a director requesting an urgent payment, a supplier asking to change bank details, or an IT colleague requesting a password reset.
Map the processes where an email, text message or Teams message can trigger an important action. Check whether staff have an independent way to verify requests involving payments, account credentials, personal data, contract changes or system access. Verification should use a known phone number or established contact route, not contact details in the message itself.
Pay particular attention to exceptions. A good approval process can fail when a senior person appears to request secrecy, urgency or a shortcut. Staff need explicit permission to pause and challenge unusual instructions, regardless of who appears to have sent them.
Test your email and identity controls
Technical controls do not eliminate phishing, but they significantly reduce the volume of malicious messages that reach users and limit the damage when one gets through. Review email filtering, attachment scanning, malicious link protection and impersonation detection. Check whether your organisation has policies for external email warnings and whether they are being used meaningfully rather than ignored through overexposure.
Identity protection deserves equal attention. Multi-factor authentication should be enabled for email, cloud applications, remote access and administrative accounts. However, not all multi-factor authentication offers the same protection. SMS codes can still be targeted through social engineering, while app-based prompts can be abused through repeated approval requests. Where the risk justifies it, phishing-resistant methods such as passkeys or hardware security keys provide stronger assurance.
Also review conditional access rules, impossible-travel alerts, privileged account management and the speed at which departed employees or changed roles lose access. A phishing email becomes far more damaging when an attacker can use a compromised account without restriction.
Measure exposure with realistic evidence
A risk assessment should rely on evidence, not assumptions. Start with security telemetry: phishing messages blocked, reported emails, login attempts from unusual locations, multi-factor authentication failures, mailbox forwarding rules and suspicious account changes. These indicators reveal whether criminals are already testing your defences.
Simulated phishing exercises can add useful insight when they are handled fairly. The goal is not to catch people out or publish a league table of failures. It is to understand which techniques cause hesitation, which departments need support and whether reporting processes work under pressure.
Use scenarios that reflect genuine risks to your business. If your organisation regularly works with contractors, test invoice fraud and supplier impersonation. If senior staff travel frequently, assess executive impersonation and fake document-sharing requests. If your teams use collaboration platforms heavily, include messages delivered through those channels rather than focusing only on email.
The results need context. A low click rate does not automatically mean low risk if employees are failing to report suspicious emails. Equally, a higher failure rate may point to a confusing process or an overly realistic test rather than poor judgement. Combine test findings with incident data, business process reviews and technical configuration checks.
Score risk in a way that drives action
Keep scoring simple enough to inform decisions. Rate each phishing scenario by likelihood and impact, then record the controls already in place and the remaining exposure. For example, supplier payment fraud may be highly likely for a finance team that deals with many external invoices and high impact because losses can occur quickly.
The most useful output is a prioritised action plan, not a lengthy report. Address risks that combine high business impact with weak or inconsistent controls first. That may mean enforcing multi-factor authentication, strengthening payment verification, removing unnecessary administrator rights or improving the reporting route for suspicious messages.
Assign an owner and a deadline to every action. Risk without ownership becomes a recurring agenda item rather than an improvement programme. Senior leadership should receive a concise view of the highest risks, the investment required and the operational consequence of doing nothing.
Turn findings into everyday protection
Effective phishing protection is a continuous operating practice. Threats change, staff roles change and attackers adapt quickly to new controls. Review phishing risk after major changes such as a cloud migration, acquisition, new finance platform, office move or supplier transition.
Make reporting easy. Staff should know exactly how to report a suspected email, text or collaboration message, and they should receive acknowledgement quickly. A visible response builds trust and encourages early reporting. It is far better to investigate ten harmless emails than to miss one fraudulent payment request.
Training should be short, specific and repeated. Generic annual modules have a role, but they are not enough on their own. Brief guidance before payroll runs, supplier onboarding or busy trading periods is more likely to influence the decision someone makes at the point of risk.
This is also where a single accountable technology partner can reduce complexity. WestTech can help businesses align managed IT, email security, identity controls, user awareness and incident response around the way their teams actually work, rather than leaving gaps between multiple providers.
Phishing risk cannot be reduced to zero, and treating every message as hostile is not practical. The aim is to make a fraudulent request difficult to deliver, difficult to act on and quick to contain. When people, processes and technology support one another, your business can keep moving without making urgency an attacker’s advantage.







